The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
{
"binaries": [
{
"binary_name": "kde-runtime",
"binary_version": "4:15.12.3-0ubuntu1"
},
{
"binary_name": "kde-runtime-data",
"binary_version": "4:15.12.3-0ubuntu1"
},
{
"binary_name": "kdebase-runtime",
"binary_version": "4:15.12.3-0ubuntu1"
},
{
"binary_name": "plasma-scriptengine-javascript",
"binary_version": "4:15.12.3-0ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "kde-runtime",
"binary_version": "4:17.08.3-0ubuntu1"
},
{
"binary_name": "kde-runtime-data",
"binary_version": "4:17.08.3-0ubuntu1"
},
{
"binary_name": "kdebase-runtime",
"binary_version": "4:17.08.3-0ubuntu1"
},
{
"binary_name": "plasma-scriptengine-javascript",
"binary_version": "4:17.08.3-0ubuntu1"
}
]
}